skills/vesely/skills/ssh-gui/Gen Agent Trust Hub

ssh-gui

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONOBFUSCATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The core functionality of the skill is to execute commands on a remote macOS host via SSH. It uses tools such as cliclick, screencapture, and osascript to perform mouse clicks, keystrokes, and screen captures.
  • [OBFUSCATION]: The bin/ssh-gui helper script uses Base64 encoding to wrap AppleScript payloads before sending them to the remote host for execution. This is implemented as a transport reliability mechanism to ensure scripts are transmitted correctly over the SSH connection.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates AppleScript strings based on the task (e.g., targeting specific application names or menu items) and executes them on the remote machine using osascript.
  • [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to ingest screenshots and UI hierarchy data from the remote system. This creates a surface for indirect prompt injection if the remote GUI displays untrusted content, such as a malicious website or document containing instructions for the agent.
  • [DATA_EXFILTRATION]: The skill allows the agent to capture and transfer images and UI state from the remote machine to its own environment. While this is the intended purpose for "driving" the GUI, it provides a functional pathway for sensitive data to leave the remote host.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:21 PM
Security Audit — agent-trust-hub — ssh-gui